CVE-2006-0423

BEA WebLogic Portal 8.1 through SP3 stores the password for the RDBMS Authentication provider in cleartext in the config.xml file, which allows attackers to gain privileges.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:oracle:weblogic_portal:8.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_portal:8.1:sp1:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_portal:8.1:sp2:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_portal:8.1:sp3:*:*:*:*:*:*

History

No history.

Information

Published : 2006-01-25 23:07

Updated : 2023-12-10 10:28


NVD link : CVE-2006-0423

Mitre link : CVE-2006-0423

CVE.ORG link : CVE-2006-0423


JSON object : View

Products Affected

oracle

  • weblogic_portal